HIGH8.8
GHSA-5f6p-4hxq-rjxm
Umbraco CMS vulnerable to CSRF
Quick fix
GHSA-5f6p-4hxq-rjxm — Umbraco.CMS: upgrade to the fixed version with the command below.
dotnet add package Umbraco.CMS --version 7.4.0Details
Umbraco before 7.4.0 allows remote attackers to bypass anti-forgery security measures and conduct cross-site request forgery (CSRF) attacks as demonstrated by editing user account information in the `templates.asmx.cs` file.
Are you affected?
Enter the version of the package you're using.